Notes from the Asia-Pacific region: China rolls out new AI governance, data protection measures

China is rapidly advancing AI governance and data protection reform through new rules for anthropomorphic AI services, financial AI use, anti-cyber violence measures, cross-border data transfers and simplified compliance for small-scale personal information handlers.

Contributors:
Barbara Li
CIPP/E
Partner
Reed Smith
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
The artificial intelligence and data space in China has been red-hot over recent few weeks — much like the weather.
WAIC
On 17 July, China's annual AI signature event — the World AI Conference 2026 — was held in Shanghai. The conference witnessed the official launch of the World AI Cooperation Organization, the world's first intergovernmental international organization dedicated to AI, with its permanent headquarters in Shanghai. The WAICO aims to advance global AI development and coordinated governance.
New anthropomorphic AI rules
China's rules governing anthropomorphic AI interactive services, effective 15 July, were among the topics widely discussed in WAIC forums. These rules require providers of AI human-like interactive products and services to implement full life cycle security management and impose clear accountability on providers to establish programs for risk assessment, ethics review, content monitoring, personal data protection, cybersecurity incident response and fraud prevention.
Providers must activate a minor mode, set up dedicated support for senior users and build in mechanisms to identify users' risky emotions or dependency and escalate to human agents in emergent situations. Given these comprehensive compliance requirements, some major platforms have suspended their human-like roleplay agent features pending further review.
Financial AI guidelines
Chinese financial regulators are also actively drafting industry-specific guidelines to provide guidance to banks and insurance companies on how to properly develop, deploy and use AI technologies in financial products and services.
Specific requirements imposed by the financial regulators include: approval by the risk control committee for high-risk scenarios, prohibition on using personal information as training data, filing of external model deployments with the Cyberspace Administration of China, and full life cycle governance, among others.
Draft Anti-Internet Violence Law
Just last week, the draft of a new national law on combating internet violence was issued for public comment. As China's first national law specifically targeting internet violence, the draft Anti-Cyber Violence Law expressly prohibits the use of deepfakes, profiling-based pushing and other AI technologies to engage in any form of internet violence.
New CAC guidelines on CBDT
Alongside these dynamic AI developments, there have been major movements in privacy and data protection.
For many data protection officers and privacy counsels, navigating China's complex cross-border data transfer regime has been no easy task. Here is some welcome news. China's national data regulator, the CAC, has issued its most recent Q&A clearing up some of the most common questions international companies face regarding cross-border transfers.
The CAC provided guidance on what information must be included in a valid separate consent and how to determine whether the outward transfer of job candidates' CVs and other personal data during the recruitment process can satisfy the "necessity" test. In addition, the CAC shed light on the conditions a business organization must meet if it wishes to renew the validity period of a cross-border transfer previously approved by the CAC.
Relaxed compliance burden for small-scale personal information handlers
More good news comes from the upcoming adoption of simplified compliance measures for small-scale personal data handlers. Starting 1 Sept., companies that process personal information of fewer than 100,000 individuals will be classified as small-scale personal data handlers and can benefit from simplified notification and consent mechanisms, extended compliance audit cycles, standardized self-assessment templates and platform-level privacy compliance.
This new development represents a significant compliance incentive for businesses, especially those with business-to-business-focused models that generally collect or process personal information of fewer than 100,000 individuals. International companies with business operations in China should assess whether their subsidiaries fall within the scope of small-scale handlers and consider practical steps to benefit from these relaxations.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEs


